Self-hosted operations control plane

One calm command center for your operational world.

Bring Docker Swarm operations, monitoring, IP resources, privileged access, work, and data tooling into one modular portal your team can run and control.

Self-hosted Role-aware Modular Private AI support
0App modules
0How-to guides
0Config topics
0+API endpoints

Why KNetraHub

Less tool switching. More operational clarity.

KNetraHub is designed for teams that have outgrown scattered commands and disconnected tools, but still want the ownership and flexibility of self-hosted infrastructure.

See the operation as one system

Connect deployment state, health signals, infrastructure inventory, access workflows, and team activity in one role-aware portal.

Turn routine work into fast decisions

Move from alert to context and from context to a safe action without switching between terminals, spreadsheets, and disconnected dashboards.

Keep ownership close

Run the platform in your own Docker Swarm, choose local accounts or enterprise identity, and keep operational control with your team.

Start focused, expand deliberately

Enable only the apps you need today, then add monitoring, IP management, privileged access, work, or database tooling as needs grow.

KNetraHub in one minute

A practical path from fragmented operations to one governed workspace.
Best fit
Teams operating Docker Swarm and adjacent infrastructure
Immediate win
One searchable place to understand and operate the environment
First deployment
Generate a ready-to-run bundle with Start Initializr
Built-in confidence
Roles, alerts, audit trails, version history, and private AI support

Product tour

See it in action

01 · Dock dashboard

Dock dashboardLive swarm overview — cluster capacity, task distribution, and per-service usage charts.

02 · Stacks

StacksGitLab-versioned compose deployments with commit history and one-click rollback.

03 · Service detail

Service detailReplicas, tasks, logs, and live usage for a single service.

04 · Nodes

NodesManager and worker fleet with availability, resources, and maintenance state.

05 · Monitoring

MonitoringUnified device inventory with status, health sensors, active alerts, and collection coverage.

06 · Work

WorkClickUp-style work management — spaces, lists, tasks, and Board/List/Table views.

07 · Privileged Access

Privileged AccessSafes hold vaulted credentials, gated by access requests, recorded sessions, and a tamper-evident audit chain.

08 · IP Management

IP ManagementSections, subnets, addresses, VLANs, and VRFs in one searchable inventory.

09 · App launcher

App launcherThe portal home lists only the apps each signed-in user may reach.

10 · Sign-in

Sign-inLocal accounts, LDAP / Active Directory, and OIDC single sign-on.

11 · Netra Private AI

Netra Private AIPrivate, on-device KNetraHub support with adaptive WebGPU and WebAssembly inference.

Core capabilities

What KNetraHub does

Stack Management

Deploy Docker Swarm stacks from compose files with full status tracking. One-click rollback with GitLab version history.

Service Control

Scale replicas, redeploy tasks, and update images across your swarm without touching the command line.

Live Monitoring

Real-time SSE event stream — swarm health at a glance: nodes, services, tasks, and cluster capacity. Metrics history is charted on node and service pages.

Alerts

Notify Telegram, Teams, or any webhook on deploy failures, usage thresholds, node-down, degraded replicas, or disk pressure — with customizable message templates.

Access Control

Tiered access per app (viewer, operator, manager, admin) with local accounts, LDAP / Active Directory, and OIDC SSO. Stored credentials are encrypted at rest.

Infrastructure

Manage networks, volumes, secrets, configs, and private registry credentials from one place.

Privileged Access

Enterprise PAM: an envelope-encrypted credential vault with online key rotation, access requests with multi-level approvals, brokered recorded sessions, just-in-time and break-glass access, and a tamper-evident audit chain.

Work Management

Clean-room ClickUp-equivalent: spaces, folders and lists; tasks with subtasks, dependencies and custom fields; List/Board/Table views; Docs, threaded comments, and time tracking.

Database Manager

Browser SQL workbench for PostgreSQL, MySQL/MariaDB, MongoDB, and Redis: governed connections with encrypted credentials, a policy-enforced editor, org-wide query oversight, and a hash-chained audit trail.

REST API

Use scoped API tokens and the interactive Swagger explorer to connect approved automation and operational integrations.

Apps

Modules in this portal

KNetraHub bundles several apps behind one portal. Each app has its own User Manual, Configuration, and API session below; portal-wide topics (authentication, users, appearance, alert delivery) live in the General sessions.

Docker

Docker Swarm management

Deploy and version compose stacks, scale and redeploy services, manage nodes, tasks, networks, volumes, secrets, configs, and private registries with live SSE monitoring.

  • Stacks & GitLab versioning
  • Services, tasks & nodes
  • Networks, volumes, secrets, configs

Monitoring

Full-stack network monitoring

SNMP/ICMP discovery and polling of routers, switches, firewalls, servers, printers, UPSes and more — one unified device model with ports, health sensors, alert rules, traps, syslog, and data-collection auditing.

  • Unified devices, ports & sensors
  • Modular discovery & polling
  • Alerting, traps, syslog & coverage

Work

ClickUp-style work management

Organise work in Spaces → Folders → Lists with object-level sharing; run tasks with subtasks, multi-assignees, dependencies, checklists and custom fields across List, Board and Table views; write Docs, comment in threads, and track time.

  • Spaces, folders & lists
  • Tasks, views & custom fields
  • Docs, comments & time tracking

Privileged Access

Enterprise privileged-access management

A cryptographic credential vault (envelope encryption, online key rotation) with safes, privileged-account onboarding and discovery, automated change/verify/reconcile, access requests with approvals, brokered recorded sessions, just-in-time and break-glass access, and a tamper-evident audit chain.

  • Encrypted vault & safes
  • Requests, approvals & sessions
  • JIT, break-glass & audit chain

IP Management

phpIPAM-style address management

Organise sections, subnets, VLANs and VRFs; inventory addresses with a visual grid; track racks, circuits, NAT and customers; and keep utilisation accurate with scheduled scans, requests, and import/export.

  • Sections, subnets, VLANs & VRFs
  • Address inventory & scans
  • Racks, circuits, requests & vault

Database Manager

CloudBeaver-style database workbench

Query PostgreSQL, MySQL/MariaDB, MongoDB and Redis targets from the browser: governed connections with envelope-encrypted credentials, a policy-enforced SQL editor with metadata navigation, org-wide query oversight, target session management, and a verifiable audit chain.

  • Connections, ACLs & policies
  • SQL editor & navigator
  • Query Manager, sessions & audit

Access & permissions

Know what each role can do

Assign the narrowest tier each person needs. Tiers apply per app — the same person can be an operator in Docker and a viewer in PAM — and are refined from Admin → Apps & Access.

Viewer
  • Dashboard & metrics
  • Stacks (read-only)
  • Services & tasks
  • Nodes
  • Networks, volumes, secrets, configs
Operator
  • All Viewer access
  • Deploy & update stacks
  • Scale & redeploy services
  • Update service images
  • Manage secrets & configs
Manager
  • All Operator access
  • Approvals & request reviews
  • Sharing & member management
  • Session monitoring (PAM)
  • Module activity & audit views
Admin
  • All Operator access
  • Manage users & roles
  • Configure LDAP & OIDC
  • Registry credentials
  • Full audit log

Getting started

Deploy with Start Initializr

Recommended: generate a ready-to-run Docker Compose bundle

Choose modules, replicas, ports, image registry, storage layout, and secrets. The knetra command installs Docker if the host lacks it, validates the manager, creates required Docker secrets, and deploys every selected stack in order — then keeps operating it with start, stop, restart, redeploy, logs and config.

1Prepare Docker Swarm
docker info --format '{{.Swarm.ControlAvailable}}'
# If this is a new single-node swarm:
docker swarm init
2Open Start Initializr
Documentation → Start Initializr
3Choose your deployment
Select modules · replicas · port
Choose one stack or separate stacks
Confirm the image registry and tag
4Install the knetra command
curl -fsSL https://sengphirum.github.io/KNetraHub/install.sh | bash
# One command, the same for everyone. Adds tab completion.
# Later: knetra update, or knetra uninstall
5Set up and deploy
knetra setup           # paste the token from Start Initializr
#   or: knetra setup --token-file token.txt
cd knetrahub
knetra install --swarm-init   # only on a host without Docker
knetra plan            # every service as Docker will resolve it
knetra start
6Verify and sign in
docker stack services knetrahub
# Open http://<manager-node>:3000
# Complete first-run setup and change the admin password

Docker Swarm Compose example

knetra start creates the required secrets before running commands like these. Use it for the first deployment; run the commands directly only after the secrets already exist.

docker stack deploy --with-registry-auth -c docker-compose.yml knetrahub
docker stack services knetrahub

Documentation sections

Explore the docs